
Robinhood · Toronto
JOIN US IN BUILDING THE FUTURE OF FINANCE. Our mission is to democratize finance for all. An estimated $124 trillion of assets will be inherited by younger gen...
Our mission is to democratize finance for all. An estimated $124 trillion of assets will be inherited by younger generations in
the next two decades. The largest transfer of wealth in human history. If you’re ready to be at the epicenter of this historic
cultural and financial shift, keep reading.
We are building an elite team, applying frontier technologies to the world’s biggest financial problems. We’re looking for bold
thinkers. Sharp problem-solvers. Builders who are wired to make an impact. Robinhood isn’t a place for complacency, it’s where
ambitious people do the best work of their careers. We’re a high-performing, fast-moving team with ethics at the center of
everything we do. Expectations are high, and so are the rewards.
The Red Team team’s mission is to proactively identify and simulate real-world threats against Robinhood’s platforms, properties,
and people. Through red teaming and adversarial simulations, the team evaluates security controls, uncovers vulnerabilities, and
helps continuously strengthen Robinhood’s overall security posture in close partnership with Detection & Response, Physical
Security, and Engineering.
As a Staff Offensive Security Engineer, you will take a hands-on role in designing and executing stealthy adversarial simulations
to validate assumptions and uncover gaps in detection and response. You’ll leverage threat modeling, penetration testing, and
research-driven techniques to emulate sophisticated attackers, while collaborating cross-functionally to improve defenses and
shape more secure systems.
This role is based in our Toronto, Canada office(s), with in-person attendance expected at least 3 days per week.
At Robinhood, we believe in the power of in-person work to accelerate progress, spark innovation, and strengthen community. Our
office experience is intentional, energizing, and designed to fully support high-performing teams.
networks, offices, and internal processes.
risk stakeholders.
techniques.
readiness.
fixes.
posts.
pipelines, and identity systems.
evasion techniques.
leaders.
programs
wellness, childcare, learning, and more.
Our team is committed to providing an inclusive and welcoming interview experience for all candidates. If you require a specific
accommodation during the application or interview process due to a physical or mental condition, please complete this Applicant
Accommodation Form to notify our team. The form should only be completed if you need a specific accommodation.
AI Usage Disclosure: Robinhood uses artificial intelligence (AI) tools to support parts of our recruiting process. These tools
enhance the efficiency and consistency of our hiring process; however, all hiring decisions are made by our hiring teams.
Vacancy Notice: This job posting represents an existing vacancy that we are actively seeking to fill.
In addition to the base pay range listed below, this role is also eligible for bonus opportunities + equity + benefits.
Base pay for the successful applicant will depend on a variety of job-related factors, which may include education, training,
experience, location, business needs, or market demands. The expected base pay range for this role is based on the location where
the work will be performed.
Toronto, ON
Click here to learn more about our Total Rewards, which vary by region and entity.
If our mission energizes you and you’re ready to build the future of finance, we look forward to seeing your application.
Robinhood provides equal opportunity for all applicants, offers reasonable accommodations upon request, and complies with
applicable equal employment and privacy laws. Inclusion is built into how we hire and work—welcoming different backgrounds,
perspectives, and experiences so everyone can do their best. Please review the Privacy Policy for your country of application.
Who we are At Twilio, we’re shaping the future of communications, all from the comfort of our homes. We deliver innovative solutions to hundreds of thousands of businesses and empower millions of developers worldwide to craft personalized customer experiences. Our dedication to remote-first work, and strong culture of connection and global inclusion means that no matter your location, you’re part of a vibrant team with diverse experiences making a global impact each day. As we continue to revolutionize how the world interacts, we’re acquiring new skills and experiences that make work feel truly rewarding. Your career at Twilio is in your hands. We use Artificial Intelligence (AI) to help make our hiring process efficient. That said, every hiring decision is made by real Twilions! . See yourself at Twilio Join the team as Twilio’s next Staff Offensive Security Engineer. About the job The Staff Engineer acts as a Technical Lead. You don't just find bugs; you design complex attack chains that demonstrate systemic risk. You spend as much time writing custom code and researching new bypasses as you do executing tests. Responsibilities In this role, you’ll: * Full-Stack Penetration Testing: Perform manual and automated testing of web applications, APIs, and mobile apps (iOS/Android). * Internal/External Network Audits: Conduct network and cloud level assessments with various tooling * Vulnerability Validation: Triage and validate reports from automated scanners or bug bounty hunters to eliminate false positives and escalate true positives * AI/LLM Probing: Perform initial prompt injection and jailbreak tests on AI prototypes, services, and applications using established checklists (OWASP Top 10 for LLMs). * Technical Reporting: Draft high-quality reports that detail the "path to compromise" with clear, reproducible steps for developers. * Tool Maintenance: Manage and update the team's testing infrastructure (e.g., Burp Suite, and basic C2 listeners). * Remediation Support: Provide direct technical guidance to engineering teams on how to patch vulnerabilities like XSS, SQLi, and IDOR. * Adversary Emulation: Design and lead multi-week Red Team operations that mimic specific threat actors (APTs) to test the SIRT detection capabilities. * Custom Exploit Development: Build custom payloads, droppers, and obfuscated scripts to bypass EDR/AV and maintain stealth. * AI Red Teaming Architecture: Build automated testing frameworks for AI systems (e.g., using PyRIT, Promptfoo, or Garak) to test for models related to sensitive data leakage. * Cloud & Infrastructure Attacks: Execute sophisticated attacks against AWS/Azure/K8s, focusing on IAM misconfigurations and container escapes. * Purple Teaming: Collaborate with SIRT and Detection Engineering to tune SIEM alerts based on the techniques used during an engagement. * Strategic Bug Bounty Management: Oversee the organization's bug bounty program, identifying trends in submissions to suggest broad architectural security changes. Qualifications Twilio values diverse experiences from all kinds of industries, and we encourage everyone who meets the required qualifications to apply. If your career is just starting or hasn't followed a traditional path, don't let that stop you from considering Twilio. We are always looking for people who will bring something new to the table! *Required: * Experience: 7-10 years in offensive security, penetration testing, a high-volume bug bounty background, AppSec, or vulnerability exploitation, and track record of finding high/critical vulnerabilities in complex environments using pentesting commercial or custom tools. * Concepts: Expert Knowledge and solid understanding of the MITRE ATT&CK matrix and the OWASP Top 10 for web applications and top 10 for LLMs, post exploitation (lateral movement, persistence, data exfiltration) and Adversarial ML. * Tooling: Proficient in OffSec popular tools like Burp Suite professional, Nmap, Metasploit, Wireshark etc... and AI security tools such as LangChain, TensorFlow for adversarial testing or, as well as use of C2 frameworks (Cobalt Strike, Sliver, Havoc) or similar tools * Scripting and Coding: Ability to write functional scripts in Python or Bash to automate repetitive testing tasks and proficiency in coding and scripting like Python, C++, and scripting for creating custom offensive exploits that avoids signature-based detection. * Certifications: Possession of advanced industry certifications such as OSCP, OSEP, OSWE, GXPN or similar training in OffSec tracks is highly desirable * Telecom expertise is preferred Desired: * Excellent written and verbal communication skills. * Ability to influence and build effective working relationships with all levels of the organization. * Proficiency in multiple languages applicable to the region. * Familiarity with localization tactics to ensure our content is accessible and inclusive across multiple APJ countries. Location This role will be remote, but is not eligible to be hired in CA, CT, NJ, NY, PA, WA. Travel We prioritize connection and opportunities to build relationships with our customers and each other. For this role, you may be required to travel occasionally to participate in project or team in-person meetings. What We Offer Working at Twilio offers many benefits, including competitive pay, generous time off, ample parental and wellness leave, healthcare, a retirement savings program, and much more. Offerings vary by location. Compensation *Please note this role is open to candidates outside of California, Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, New Jersey, New York, Vermont, Washington D.C., and Washington State. The information below is provided for candidates hired in those locations only. The estimated pay ranges for this role are as follows: * Based in Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, Vermont or Washington D.C. : $155,520.00 - $194,400.00. * Based in New York, New Jersey, Washington State, or California (outside of the San Francisco Bay area): $164,640.00 - $205,800.00. * Based in the San Francisco Bay area, California: $182,960.00 - $228,700.00. * This role may be eligible to participate in Twilio’s equity plan and corporate bonus plan. All roles are generally eligible for the following benefits: health care insurance, 401(k) retirement account, paid sick time, paid personal time off, paid parental leave. The successful candidate’s starting salary will be determined based on permissible, non-discriminatory factors such as skills, experience, and geographic location. Applications for this role are intended to be accepted until 31st August 2026, but may change based on business needs. Twilio thinks big. Do you? We like to solve problems, take initiative, pitch in when needed, and are always up for trying new things. That's why we seek out colleagues who embody our values — something we call Twilio Magic. Additionally, we empower employees to build positive change in their communities by supporting their volunteering and donation efforts. So, if you're ready to unleash your full potential, do your best work, and be the best version of yourself, apply now! If this role isn't what you're looking for, please consider other open positions. Twilio is proud to be an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Qualified applicants with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Additionally, Twilio participates in the E-Verify program in certain locations, as required by law.
RDQ426R108 This role is open to candidates in the US (any location) ABOUT THE TEAM The AI Security team at Databricks sits at the frontier of securing the AI/ML services in the Databricks platform. As we ship AI capabilities at the leading edge of the industry, including Agent Bricks, the Genie suite, AI Model Serving, MLflow, and Unity AI Gateway, the AI Security team ensures these systems are designed, built, and operated securely. Our work also extends to securing our own usage of AI: building the right guardrails that enable Databricks employees to innovate and deliver securely. The team combines offensive security depth with AI/ML engineering knowledge to identify novel threats, build scalable defenses, and influence how AI products are architected from the ground up. We lead AI Red Team exercises, build security tooling for AI workloads, and partner directly with AI Product teams to embed security into the development lifecycle. --- THE ROLE As a Staff Security Software Engineer on the AI Security team, you are a senior technical leader who sets the standards for how Databricks secures its AI and ML capabilities. You combine deep offensive security expertise with practical knowledge of AI/ML systems to identify and drive resolution of the most significant security risks in Databricks' AI platform. You lead AI red team engagements against production AI systems, conduct security architecture reviews for complex, multi-system AI features, and build the tooling and frameworks that scale the team's impact. You are a subject matter expert in at least two AI security domains and you operate with significant autonomy- driving cross-team remediation, setting technical standards, and mentoring teammates in both offensive techniques and secure AI design. --- THE IMPACT YOU WILL HAVE AI RED TEAM & ADVERSARIAL TESTING * Lead AI red team engagements against Databricks' production AI systems, including Foundation Model APIs, Genie and natural language query systems, Model Serving infrastructure, MCP-connected agents, and RAG pipelines * Design and execute adversarial attack scenarios: prompt injection, jailbreaking, memory poisoning, cross-tenant data leakage in multi-tenant serving, and sandbox bypasses * Develop proof-of-concept exploits for AI-specific vulnerability classes and perform variant analysis to identify the full scope of exposure across the AI platform * Contribute to the evolution of the Databricks AI Security Framework (DASF), maintaining and extending the risk taxonomy, control library, and testing methodology as AI capabilities evolve AI PRODUCT SECURITY & ARCHITECTURE REVIEWS * Lead comprehensive security architecture reviews for complex AI features: threat modeling agentic workflows, RAG pipelines, multi-model serving chains, and MCP-based tool integrations * Partner directly with AI and ML engineering teams to identify security risks early in the design process and define practical, scalable controls * Assess and drive resolution of cross-cutting AI security risks: Unity Catalog permission enforcement in AI contexts, inference data isolation, model artifact integrity, fine-tuning pipeline security, and external model API governance via AI Gateway * Identify recurring security patterns across AI features; advocate for class-level architectural fixes rather than feature-by-feature point solutions AI SECURITY TOOLING & AUTOMATION * Design and build automated AI security testing tooling, including adversarial prompt libraries, agent behavior analysis frameworks, and continuous testing harnesses * Build AI-assisted automation that scales security reviews, threat modeling, and vulnerability triage for AI features * Develop and maintain security guardrails and enforcement mechanisms: LLM-as-judge review, prompt delimiting, output validation, rate limiting, and audit logging CROSS-TEAM REMEDIATION & STANDARDS * Set technical standards for how AI security risks are assessed, prioritized, and remediated across the engineering organization * Drive cross-team remediation for significant AI security findings, defining fix requirements, validating patches, and ensuring regression coverage in CI/CD pipelines * Produce high-quality threat models, security advisories, and post-mortems that inform organizational risk decisions for AI products MENTORSHIP & COMMUNITY * Mentor engineers on the AI Security team in adversarial ML techniques, AI threat modeling, and security tooling development * Contribute to internal knowledge assets, including training materials, design patterns, and threat model templates, that raise AI security fluency across the engineering organization * Represent Databricks in the external AI security community through publications, conference talks, or open-source contributions --- WHAT WE LOOK FOR * 7–10 years of combined experience in offensive security, AI/ML security research, or product security engineering, with demonstrated leadership in securing complex systems * Subject matter expert in at least two of the following AI security domains: - LLM and generative AI security (prompt injection, jailbreaking, training data extraction) - AI agent and orchestration security (MCP, memory sharing, multi-agent systems) - ML infrastructure and serving security (model serving multi-tenancy risks, training infrastructure security) - AI data governance and privacy (fine-grained access control, data residency, inference data isolation) * Demonstrated ability to design and execute adversarial attacks against production AI systems * Deep understanding of AI/ML platform architecture- how models are trained, served, and integrated, and where the trust boundaries between components lie * Expert in at least one major cloud platform (AWS, Azure, GCP) and its AI/ML security model * Proficient in Python; able to read and analyze ML model code, training scripts, and API serving code; working knowledge of at least one additional language (Go, Java, Scala, Rust) * Track record of driving cross-team AI security improvements and influencing product architecture decisions * Experience building automated security tooling for AI systems * Strong communicator- translates AI security risks into actionable guidance for engineers, product managers, and leadership * Pragmatic approach to risk- distinguishes real-world exploitable AI risk from theoretical concerns NICE TO HAVE * Published research on AI/ML security topics or experience presenting at AI security venues (DEF CON AI Village, NeurIPS workshops, Black Hat) * Experience with OWASP Top 10 for LLMs, MITRE ATLAS, or similar AI security frameworks * Familiarity with MLflow, Unity Catalog, Delta Lake, or Databricks platform internals * OSCP or equivalent offensive security certification * Academic or research background in machine learning, adversarial ML, or AI safety --- WHY DATABRICKS On the AI Security team, you'll work on a class of security problem that didn't exist five years ago, and that the industry is still figuring out. You'll run red team engagements against a live AI platform used by over 12,000 organizations, build tooling that has no precedent to copy, and drive security decisions that shape how AI products are built across the company. The problems are novel, the stakes are real, and the team working on them is exceptional. About Databricks Databricks is the data and AI company. More than 10,000 organizations worldwide — including Comcast, Condé Nast, Grammarly, and over 50% of the Fortune 500 — rely on the Databricks Data Intelligence Platform to unify and democratize data, analytics and AI. Databricks is headquartered in San Francisco, with offices around the globe and was founded by the original creators of Lakehouse, Apache Spark™, Delta Lake and MLflow. To learn more, follow Databricks on Twitter, LinkedIn and Facebook. Benefits At Databricks, we strive to provide comprehensive benefits and perks that meet the needs of all of our employees. For specific details on the benefits offered in your region click here. Our Commitment to Diversity and Inclusion At Databricks, we are committed to fostering a diverse and inclusive culture where everyone can excel. We take great care to ensure that our hiring practices are inclusive and meet equal employment opportunity standards. Individuals looking for employment at Databricks are considered without regard to age, color, disability, ethnicity, family or marital status, gender identity or expression, language, national origin, physical and mental ability, political affiliation, race, religion, sexual orientation, socio-economic status, veteran status, and other protected characteristics. Compliance If access to export-controlled technology or source code is required for performance of job duties, it is within Employer's discretion whether to apply for a U.S. government license for such positions, and Employer may decline to proceed with an applicant on this basis alone.
회사 소개 쿠팡은 고객 감동 실현을 위해 존재합니다. 고객들이 "쿠팡 없이 그동안 어떻게 살았을까?" 라고 말할 때, 비로소 우리의 미션을 실현하고 있음을 알 수 있습니다. 고객들의 쇼핑과 식사, 생활 전반을 편하게 만들겠다는 유일한 집념으로 쿠팡은 수억 달러 규모의 커머스 산업 전반의 혁신을 이끌고 있습니다. 쿠팡은 가장 빠르게 성장하는 리테일 기업 중 하나로, 국내 커머스 업계에서의 독보적인 입지와, 고객 신뢰를 구축했습니다. 쿠팡은 스타트업 문화를 기반으로 한 글로벌 대형 상장사라고 자부합니다. 이것이 창립 당시의 기민함을 유지하며, 신규 서비스를 끊임없이 출시하며 비즈니스를 확장해 나가는 우리의 성장 동력입니다. 쿠팡의 모든 임직원에게는 기업가 정신을 갖추고 새로운 혁신과 이니셔티브를 추진할 수 있는 기회가 주어집니다. 주저없이 일에 뛰어들어 성과를 이루고자 하는 과감성이, 바로 쿠팡이 일하는 방식의 본질입니다. 쿠팡에서는 여러분 자신, 동료, 팀 그리고 회사 전체가 매일 성장하는 모습을 목격할 것입니다. 쿠팡의 모든 직원은 커머스의 미래를 만들겠다는 쿠팡의 미션에 진심입니다. 우리는 고객의 문제를 해결해 나가고, 전통적인 관념과 통념에 맞서며 실현가능한 한계를 뛰어넘고 있습니다. 고가용성(Always-on) 과 최첨단의 앞선 기술(High-tech), 초연결사회(Hyper-connected world) 에서의 놀라운 업무 경험을 원하신다면, 지금 바로 쿠팡에 합류하세요. 직무 소개 서울 오피스에서 함께할 새로운 레드팀(Red Team) 멤버를 찾고 있습니다. 이상적인 후보자는 보안(Security)에 대한 열정을 가지고 있으며, 잠재적인 보안 취약점을 발견하고 이를 깊이 있게 분석하는 것을 즐기는 분입니다. 보안 취약점을 찾아내고, 이를 활용해 기술적 보안 통제를 우회하는 과정에 흥미를 느끼신다면, 여러분의 지원을 기다립니다. 업무 내용 * 웹(Web), 모바일(Mobile), API, 네트워크 대상 침투 테스트 수행 * 수행한 테스트에서 발견된 보안 이슈에 대해 개선 방안 및 대응 가이드 제공 * 위협 행위자 시뮬레이션 활동 수행 (레드팀 캠페인 운영) 자격 요건 * 공격 보안(Offensive Security) 분야에서 5년 이상의 기술적 업무 경험 * 웹, 모바일, API 보안 테스트 수행 역량 * 주요 침투 테스트 도구 활용 경험 (예: Burp Suite, Metasploit, Kali Linux, Nmap 등) * 운영체제 보안(예: Linux) 및 네트워크(TCP/IP)에 대한 이해 * Linux 및 커맨드라인 도구 활용 능력 * 테스트 자동화 및 보조 도구 개발을 위한 프로그래밍 역량 (예: Python, Java 등 최소 1개 이상 언어 숙련) 우대 사항 * 이커머스(e-commerce) 분야 근무 경험 * 클라우드 환경(예: AWS)에 대한 경험 및 온프레미스 데이터센터와의 차이에 대한 이해 * Cyber Kill Chain, MITRE ATT&CK 프레임워크에 대한 이해 * 컴퓨터공학, 컴퓨터공학 관련 또는 유사한 기술 학위 보유 * 공신력 있는 공격 보안 인증 보유 (예: OSCP, OSCE, OSED, CREST, SANS 등) * 한국어 및 영어 모두 능통한 분 전형 절차 및 안내 사항 * 전형 절차 * 서류전형 - 전화면접 - 대면(화상)면접 – 최종 합격 * 전형절차는 직무별로 다르게 운영될 수 있으며, 일정 및 상황에 따라 변동될 수 있습니다. * 전형 일정 및 결과는 지원서에 등록하신 이메일로 개별 안내 드립니다. * 참고 사항 * 본 공고는 모집 완료 시 조기 마감될 수 있습니다. * 지원서 내용 중 허위사실이 있는 경우에는 합격이 취소될 수 있습니다. * 취업 보호 대상자(보훈대상자, 장애인 등)는 관련 법률에 따라 채용우대를 받을 수 있습니다. * 직급과 담당 업무 범위는 후보자의 전반적인 경력과 경험 등 제반사정을 고려하여 변경될 수 있습니다. 이러한 변경이 필요할 경우, 최종 합격 통지 전 적절한 시기에 후보자와 커뮤니케이션 될 예정입니다. * 채용 및 업무 수행과 관련하여 요구되는 법령상 자격이 갖추어지지 않은 경우 채용이 제한될 수 있습니다. 개인정보 처리방침 * 쿠팡 그룹은 입사지원자 개인정보 처리방침(아래 링크)에 따라 귀하의 개인정보를 수집하여 처리합니다. https://www.coupang.jobs/kr/privacy-policy 서류 반환 정책 1. 본 고지는 『채용절차의공정화에관한법률』 제11조제6항에 따른 것 입니다. 2. 당사 채용에 응시한 구직자 중 최종 합격이 되지 못한 구직자는 『채용절차의 공정화에 관한 법률』에 따라 제출한 채용서류의 반환을 청구할 수 있음을 알려 드립니다. 다만, 홈페이지 또는 전자우편으로 제출된 경우나 구직자가 당사의 요구 없이 자발적으로 제출한 경우에는 그러하지 아니하며, 천재지변이나 그 밖에 당사에게 책임 없는 사유로 채용서류가 멸실된 경우에는 반환한 것으로 봅니다. 3. 위2항 본문에 따라 채용 서류 반환 청구를 하는 구직자는 채용 서류 반환 청구서 [채용절차의 공정화에 관한 법률 시행규칙 별지 제 3 호 서식]를 작성하여 이메일 (recruitingops@coupang.com) 로 제출하면, 제출이 확인된 날로부터 14 일 이내에 지정한 주소지로 등기우편을 통하여 발송해 드립니다. 이 경우 등기우편요금은 수신자 부담으로 하게 되오니 유념하시기 바랍니다. 4. 당사는 위2항 본문에 따른 구직자의 반환 청구에 대비하여 채용 여부가 확정된 날로부터 180 일간 구직자가 제출한 채용서류 원본을 보관하게 되며, 그때까지 채용서류의 반환을 청구하지 아니할 경우에는 『개인정보 보호법』에 따라 지체 없이 채용서류 일체를 파기할 예정입니다. 5. 단, 위 1항 내지 4항의 내용은 대한민국의 노동 관계 법령이 적용되는 경우에만 적용됩니다. 그 이외의 경우에는 적용되지 않습니다.